Security Features on Bitget: 2FA, Anti-Phishing, Device Control and Withdrawal Protection
From passkeys and Google Authenticator to anti-phishing codes, a fund password and withdrawal allowlists, this guide shows how to build layered protection for a Bitget account.
A Bitget account should not rely on the login password alone. A more durable setup splits protection into four layers: lock the login, verify official messages, restrict devices and sensitive actions, and protect withdrawals. A passkey reduces phishing-login risk; it does not replace a withdrawal-address check. An allowlist restricts where funds can leave; it does not replace email and device security.
TL;DR
- Protect the registration email first, then set a unique Bitget login password.
- Enable a passkey or Google Authenticator, and set an anti-phishing code.
- Review login devices and API keys regularly, and remove anything you do not recognise.
- Protect the cash-out path with a separate fund password, a withdrawal allowlist and cross-device confirmation.
Start here: security should be layered
Bitget account security is not a single password. It is a stack of login verification, device control, anti-phishing, a fund password and withdrawal protection. Split the work into four layers:
Layer 1: Protect the login
Layer 2: Verify official messages
Layer 3: Restrict devices and sensitive actions
Layer 4: Protect withdrawals and the cash-out pathDo these first: give the registration email a unique, strong password; enable a passkey or Google Authenticator; set an anti-phishing code; review login devices and API keys; set a separate fund password; configure a withdrawal allowlist and cross-device confirmation; if something looks wrong, stop and contact official support.
No single control covers every risk. A passkey reduces phishing-login risk but does not replace a withdrawal-address check. An allowlist restricts where funds can leave but does not replace email and device security.
What security features does Bitget provide?
| Layer | Feature | Main job |
|---|---|---|
| Login protection | Passkey | Verify identity with a device, biometrics or a security key |
| Login protection | Google Authenticator | Provide a time-based code for login, withdrawals and sensitive settings |
| Message verification | Anti-phishing code | Help recognise official email, SMS or login screens |
| Account control | Device management | View and remove unrecognised login devices |
| Account control | Login password | Stop credentials being guessed or reused |
| Funds protection | Fund Code | Confirm withdrawals, P2P and other sensitive actions |
| Trading protection | PIN Code | Confirm some trading and payment actions |
| Withdrawal protection | Address allowlist | Allow withdrawals only to saved, approved addresses |
| Withdrawal protection | Cross-device confirmation | Confirm a withdrawal address on a second device |
| Withdrawal protection | Cancel withdrawal | Cancel a suspicious or mistaken request inside the allowed window |
| Incident response | Remove device, delete API, freeze account | Stop further action after unexpected access |
Features, entry points and availability can differ by account, region, device and product version. Use what the current Bitget security centre shows.
Layer 1: Protect the email and the Bitget account with unique passwords
Account recovery and security notices usually depend on the registration email. If the mailbox is taken over, an attacker may still try to receive codes, reset the password or hide alerts even if the Bitget password has not leaked.
- Do not reuse the mailbox password as the Bitget login password
- Do not reuse passwords from other exchanges, social apps or forums
- Store a random password in a password manager
- Never send passwords, codes or identity documents to anyone claiming to be support
- Do not stay signed in on public devices
- Do not open the login page from unknown search-ad links
If several platforms share one password, a leak in one place can expose the others at the same time.
Layer 2: Prefer a passkey or Google Authenticator
How does a passkey protect the account?
A passkey is a device-based, passwordless method. You confirm login or sensitive actions with a fingerprint, face unlock, device PIN, screen lock, or a hardware key such as a YubiKey.
Bitget’s notes describe a public/private-key design: the platform stores the public key, the private key stays on the user device and does not leave it during login. Passkeys are also bound to the site domain, so they usually cannot be invoked on a lookalike phishing page. That makes them stronger against fake login pages than typing a password and a code by hand.
Who should use a passkey?
- People who mainly sign in on their own phone or computer
- People who want fewer password and OTP prompts
- People using a modern browser and device lock
- People who can manage more than one trusted device
- Higher-security users with a hardware security key
Watch for these:
- Do not keep the only passkey on a device that is easy to lose
- Check that the device account and screen lock are themselves secure
- Review saved passkeys from time to time
- Remove a key when the device is transferred, lost or retired
How does Google Authenticator protect the account?
OTP apps such as Google Authenticator generate short-lived codes. Bitget’s guide uses them for two-factor authentication, and notes that login, withdrawals, password changes and security-setting changes may require the authenticator.
- Keep the backup key shown during setup
- Store that backup key offline
- Never send the QR code or setup secret to anyone
- Do not store the authenticator backup next to the Bitget password
- Confirm a recovery path before changing devices
If the authenticator and the Bitget app sit on the same phone, losing the phone can remove both login and verification at once, so prepare a recovery path in advance. Bitget’s account-security notes prefer Google Authenticator and passkeys, and warn that SMS codes can face SIM swapping or malware that reads messages.
Layer 3: Set an anti-phishing code to verify official messages
An anti-phishing code is a phrase you set yourself. After it is configured, you can check whether an email, SMS or login screen matches the code you saved.
Bitget’s notes say the code can appear in official communications and login-related screens. If it is missing or does not match, stop interacting with that message or page and verify through an official channel.
How should the code be set?
- Use something you recognise but others cannot guess
- Do not reuse the login password
- Do not reuse the Google Authenticator secret
- Do not use an ID number, phone number or birthday
- Do not tell it to anyone claiming to be support
- Check the code shown in official emails from time to time
What it does not replace
- Password
- Passkey
- Google Authenticator
- Withdrawal allowlist
- URL checks
- Official-channel verification
Its job is to help you decide whether a message looks genuine. It does not stop an attacker from signing in.
Layer 4: Confirm the site, app and social accounts are official
A phishing site can look almost identical to the real page and only change the domain spelling, path or a character. Bitget’s security notices tell users to stick to official domains and the official app, and to avoid scanning unknown QR codes, clicking unfamiliar links, or sending account details through unverified support channels.
Bitget also provides an official-channel checker for website links, email addresses, social accounts and other channels claiming to belong to Bitget. If the result is not official, you can report the suspicious link or account through that tool.
A quick check before you sign in
The domain is spelled correctly
The browser connection looks normal
The page was not opened from an unknown short link
Nobody is asking for a private key or seed phrase
Nobody is asking to remote-control the device
Nobody is asking you to send funds to a “verification” addressAnyone claiming to be support and asking for a password, private key, seed phrase or 2FA code should be treated as high risk.
Layer 5: Review login devices and sessions
Device management shows which devices have signed in. Check device name, system type, login time, location, and whether the device is yours.
If you see a device you do not recognise, do this first:
- Remove the unknown device
- Change the login password
- Check mailbox security
- Check 2FA settings
- Check withdrawal history
- Check API keys
- Contact official support
Bitget’s hijacked-account guide tells users to open the login-device list and delete unrecognised devices. After deletion, that device is signed out immediately.
What device removal cannot do
- Reverse a completed on-chain transfer
- Recover a compromised mailbox by itself
- Delete an already leaked API key
- Replace changing the password and 2FA
So if an unknown device appears, check the other layers at the same time.
Layer 6: Review API keys
If the account uses a quant tool, trading bot or third-party service, an attacker may trade or read account data through an API key.
- Whether any API key is unrecognised
- Whether it has trading permission
- Whether withdrawal permission is enabled
- Whether an IP allowlist is set
- Whether the related program is still in use
- Whether the creation time looks reasonable
If a key looks suspicious, delete it. Changing the login password is not enough. Bitget’s hijacked-account guide also tells users to open the API key page and remove any unauthorised or suspicious access. Delete keys for bots, programs or services you no longer use instead of leaving them in place.
Layer 7: Set a separate fund password
The fund password and the login password do different jobs. Bitget’s account-security notes describe Fund Code as a security password for sensitive actions such as withdrawals and some security settings. PIN Code is used in some spot-trading and Bitget Pay scenes.
Keep it different from the login password
Do not use:
- The login password
- The mailbox password
- The phone PIN
- Google Authenticator codes
- Easy number sequences
- A birthday or phone number
Even if an attacker has the login password, they still need a second, independent check to complete a sensitive action.
If the login password and fund password are the same, that extra isolation is much weaker.
Layer 8: Configure a withdrawal-address allowlist
An allowlist limits withdrawals to wallet addresses already saved and approved in the address book. Bitget’s withdrawal-settings notes say that after it is enabled, funds can only go to those trusted addresses, which reduces the chance of an attacker sending assets to a new address.
Allowlist habits
- Save only wallet addresses you can verify
- Give each address a clear label
- Save different networks for the same asset separately
- Test with a small amount first
- Do not paste unknown addresses from chat apps
- Do not add addresses during remote control or screen sharing
- Delete addresses you no longer use
An allowlist does not replace a network check
Even if the address is already allowlisted, still confirm the asset, network, address format, whether a memo/tag is required, and whether the receiving platform supports that network. An allowlist only restricts the destination. It does not judge whether the network and asset match.
Layer 9: Use cross-device withdrawal confirmation
Cross-device confirmation lets you submit a withdrawal on one device and check the address on another trusted device. Bitget describes this as a way to catch a tampered or hijacked address on web: you can confirm in the app whether the address typed on the website is the one you intended.
- Larger withdrawals
- People who use both web and the mobile app
- Concern about clipboard or browser malware on a computer
- Splitting submit and confirm across devices
When confirming, check the full address, not only the first and last characters.
Layer 10: Use cancel-withdrawal and password-free small withdrawals with care
Cancel withdrawal
Bitget’s withdrawal-settings notes say that, when enabled, a withdrawal can be cancelled within one minute after submission. That can correct a typing error or stop an unauthorised request quickly. The window is short. It does not replace an allowlist, 2FA, a fund password, a pre-withdrawal check or device security.
Password-free small withdrawals
This reduces verification on frequent small transfers, but fewer checks also means a thinner security layer. If you do not have a clear high-frequency need, a security-first user can leave it off.
- Use it only with trusted allowlisted addresses
- Keep the limit low
- Test with a small amount first
- Review trusted addresses regularly
- Turn it off immediately after a device incident
Limits and availability should be read from the current security centre.
Why withdrawals may pause after a security change
Bitget’s notes say that after resetting a password, changing the fund password, resetting or changing 2FA, or changing email or phone number, withdrawals may be limited for 24 hours. After signing in on a new device, payments and withdrawals on that device may pause for 1 hour. These holds are meant to reduce the risk of funds leaving immediately after a security change.
So before a planned withdrawal, avoid a last-minute password reset, 2FA reset, phone or email change, fund-password change, or first login on a new device. The exact hold time and conditions can change; use the prompt on the account page.
What to do if the account looks compromised
If you see an unknown device, unusual login, unknown API key, suspicious withdrawal or unexpected asset movement, stop trading and withdrawing, then work through this order.
1. Change the password
Also check whether the registration email is still under your control.
2. Remove unknown devices
Delete unrecognised sessions in device management.
3. Delete suspicious API keys
Pay special attention to trading and withdrawal permissions.
4. Enable or reset 2FA
Make sure the authenticator and passkeys are under your control.
5. Check withdrawal addresses and history
Look for unknown addresses or unauthorised requests.
6. Contact Bitget official support
If you cannot control the account, or you think the attack is still ongoing, request a temporary freeze through the official Help Center or live chat. Bitget’s guide says support may freeze the account during an investigation to stop further unauthorised action.
7. Keep evidence
- Login alerts
- Suspicious emails
- Chat records
- Screenshots
- Transaction IDs
- Withdrawal addresses
- Device and time details
Completed on-chain transfers usually cannot be reversed by the platform, so earlier reporting is more useful for stopping further loss.
Common mistakes
Mistake 1: SMS codes are enough
SMS can face SIM swapping, malware that reads messages, or other communication risk. A passkey or authenticator is the more durable pairing.
Mistake 2: 2FA means you can skip device checks
If an existing device session, mailbox or API key is already controlled, 2FA does not clear those access paths by itself.
Mistake 3: An anti-phishing code stops account takeover
The code helps you recognise messages. It does not replace passwords and withdrawal protection.
Mistake 4: An allowlisted address cannot go wrong
The wrong asset, network or memo/tag can still send funds somewhere they cannot be recovered.
Mistake 5: You can withdraw immediately after changing the password
A security-setting change can trigger a temporary withdrawal hold.
Mistake 6: Support will ask for a code to verify you
Bitget’s official security notes say the platform will not ask users for passwords, private keys or 2FA codes.
Account security checklist
Login and verification
- Bitget and the mailbox use different passwords
- The mailbox has 2FA enabled
- Bitget has a passkey configured
- Bitget has Google Authenticator configured
- The authenticator backup key is stored offline
Anti-phishing
- An anti-phishing code is set
- The code is checked in emails
- The domain is checked before login
- Unknown QR codes are not scanned
- Unknown “support” links are not used to sign in
Devices and APIs
- Login devices have been reviewed
- Unknown devices have been removed
- API keys have been reviewed
- Unused API keys have been deleted
- API permissions are limited to what is actually needed
Funds and withdrawals
- A separate fund password is set
- Trusted withdrawal addresses are saved
- The withdrawal allowlist is enabled
- Cross-device confirmation is enabled
- Asset, network, address and memo/tag are checked before sending
- Large withdrawals start with a small test
Incident response
- You know the official Help Center and support entry
- You know how to remove a device
- You know how to delete an API key
- You know how to request an account freeze
- You know which trade and message evidence to keep
In short
Bitget’s account-security features can be read as four layers:
Login protection
→ passkey, password, Google Authenticator
Message verification
→ anti-phishing code, official-channel checks
Account control
→ device management, API management, fund password
Cash-out protection
→ withdrawal allowlist, cross-device confirmation, cancel withdrawalFor most users, the highest-value set is:
Unique passwords
+ passkey or Google Authenticator
+ anti-phishing code
+ device and API review
+ fund password
+ withdrawal allowlistSecurity setup is not a one-time task. After changing a device, email, phone number, adding an API key, or seeing a suspicious notice, open the security centre again.
Notes
This guide is based on Bitget’s publicly available materials. Security features, entry points, withdrawal settings, verification methods and temporary holds can change by region, account type, device and product version. Use the current Bitget security centre and the latest official information.